Someone with the intent and know-how to crack RFID readers could put together a hardware tool to do so. Does the Flipper Zero provide such a tool? Yeah. Does the responsibility of following ethics fall with the user? Debatable, but I think absolutely yes.
If one carries around a lockpicking set and learns how to use it, they can go right ahead, correct? We accept the fact that people exist that can pick locks and yet 80% of states allow possession and use of lockpicking tools in a legal manner.
Saying "RFID is insecure, use NFC" is like saying "radio is insecure, use WiFi." NFC is a subset of the concept of RFID, much the same way WiFi is a subset of digital radio protocols.
RFID, while versatile and utilized across a range of applications from inventory management to access control, does not inherently prioritize security to the same extent. Its broader application spectrum means that specific security measures can vary significantly based on the use case and the design of the RFID system. For example, passive RFID tags, which are widely used due to their cost-effectiveness and simplicity, can be read from distances up to several meters, potentially exposing them to unauthorized scans. Active RFID tags offer longer read ranges and can incorporate additional security features, but their cost and complexity limit their use to specific applications.
Therefore, when comparing the security aspects directly, NFC's design principles inherently prioritize secure exchanges, leveraging close proximity communication and encryption standards that are well-suited for transactions and sensitive data exchanges. This focus on security, combined with the technology's adaptability for consumer use (e.g., smartphones for payments), underscores NFC's advantage in scenarios where security is paramount.
Most hotels use non-NFC RFID and on top of that most use passive tags. So it is certainly an inherent security flaw of hotel door locks. Unfortunately non-meatspace security is also drastically in need of choosing more effective already existing measures.
Base NFC has almost no security and relies on protocols on top to be secure. For example, Amibos use NFC and are trivially duplicated with cheap writable NFC tags. Contactless credit cards aren't secure because they do NFC, they're secure because NFC allows for an EMV transaction, it's the EMV handshake that handles all the security.
Once again, suggesting NFC just has a lot of security by default is acting like WiFi is always secure. But even worse, because at least WiFi standards have encryption and what not built in and optional, NFC doesn't even provide that.
And then you point out passive tags as if that's a thing that makes RFID less secure (ignoring NFC used for identification is RFID) but then I guess don't realize NFC allows for passive tags as well. I don't need to change batteries on my Amibos or the NFC stickers I put on the Wi-Fi info around the house.
You could build a key card system with NFC that has the same or worse system as older key card platforms. It being NFC gives you absolutely no additional benefit.
I actually will also correct myself about saying that NFC is shorter range than RFID. Both HF and LF have about the same range. UHF has a range on the order of 10m but is almost never if at all used for high volume applications like hotel door locks. I do however disagree with your rejection of the colloquial usage of RFID to exclude NFC. In everyday conversation, I believe it is understood that NFC is a subset.
> NFC's design principles inherently prioritize secure exchanges
NFC's design principles inherently has absolutely zero security. It doesn't prioritize secure exchanges, at all. The fact secure exchanges can happen over NFC in incidental to NFC existing. Any secure exchange that happens over NFC happens because the higher-level application brought its own security.
It's like UDP. Sure, you can do a secure exchange of data using it like QUIC or encrypted RTP, but UDP doesn't give you anything other than a way to send that data along.
Which then compared to just an overall massively wide topic like "RFID", which encompasses dozens (hundreds?) of other technologies, some of which do actually prioritize secure (or at least attempted to secure) handshakes throughout the entire stack.
And range of an RF thing is largely just based around typical hardware. If you wanted to you could build an antenna array to pick up an NFC tag from dozens of meters away. WiFi might only be designed to work around the house, but with a clear line of sight, decent RF conditions, and the right antennas you can send it miles.
Generally speaking, you shouldn't expect any kind of security doing things with NFC. Because, NFC has no security inherent to the protocol.
In general it's probably okay to bring your picks somewhere in most parts of the country if you're a hobbyist.
In general it's a bad idea to carry picks if you're doing anything that a prosecutor could construe as breaking into a building to steal things. This is an area to be particularly aware of for urban exploration, where trespassing is bad but burglary with burglarious tools is like felony bad.
However, that is a fairly extreme case, and most countries don't have such laws on the books (or if they do, what's illegal is "possession with intent").
But a lockpicking kit has one purpose, it's picking locks. A Flipper Zero type device has plenty of legitimate, legal, personal uses in an IoT equipped home.
The Flipper Zero being banned will lead to a flood of copies, not to mention black market OEM versions.
Banning things doesn't make them impossible to get hold of but it does make it harder/more costly, which is all that any anti-crime measure can hope to achieve. Why do you say the opposite effect? This isn't like alcohol (or even, to an extent, weed) where a majority of ordinary decent people use it occasionally and want it to be available. Most people have never owned or used lockpicks and don't see any reason to have them if you're not a criminal. (And, sadly, that's probably also true of a flipper zero).
In the United States, postal services have access to clusters of mailboxes and some common areas where mailman can leave mail and parcels, which can be entryways or some kind of storage rooms in them, for example, so that the owners can pick them up when they get home. These rooms are locked with padlocks made by several local companies. Once a key is inserted and turned in the lock, it can only be retrieved by turning it in the opposite direction to the default position, but even then they manage to forget them in the locks.
A customer from the USA came to us and asked us to combine this padlock with an intercom system we are developing to signal the administrator that the letter carrier came, opened/closed the lock or forgot the key in it. Nobody wants to switch to RFID, of course, or else the employees of the lock manufacturing company will have nothing to eat, so we had to enlarge the intercom vertically in order to build into it a lock whose transom will close a group of contacts on the panel, letting us know that something is going on. On the edge, lmao.
In the UK, mailmen are treated very differently - the intercoms have a special button on the intercom which, when pressed, will open the door so that the mailman can enter and drop off the mail without having to carry keys or RFID identifiers. Normally this button is set for some working hours, for example from 9 to 5 and of course anyone can press it and get into the premises.